TL;DR: Agentic AI fraud now operates as a 24-hour attack factory that generates synthetic identities, adapts across sessions, and uses legitimate or compromised access paths at the interaction layer, according to Arkose Labs, while the World Economic Forum reports 73% of respondents were personally affected by cyber-enabled fraud in 2025. Identity verification alone fails when behaviour changes mid-session and success depends on observing what the actor does, not just who it claims to be.
Editorial analysis by NHI Mgmt Group, based on content published by Arkose Labs: “The Attack Runs Itself: What Agentic AI Fraud Actually Looks Like”.
By the numbers:
- 73% of respondents were personally affected by cyber-enabled fraud in 2025, according to the World Economic Forum's Global Cybersecurity Outlook 2026 cited by Arkose Labs.
Key questions
Q: What breaks when agentic AI fraud is judged only by identity signals?
A: Identity-only fraud controls break when the actor can change tactics after sign-in.
Q: Why do agentic fraud campaigns make mid-session adaptation so dangerous?
A: Because the system can learn from each failure and change the next attempt without waiting for human guidance.
Q: How can IAM teams tell whether fraud controls are actually working?
A: Look for fewer unverified high-risk requests, better challenge rates on abnormal approvals, and stronger separation between routine identity events and exceptional transactions.
Practitioner guidance
- Instrument critical journeys for behavioural trust Add telemetry to account creation, login, MFA, checkout, and API-driven flows so you can detect adaptive retries, scripted navigation, and session-to-session learning.
- Separate identity proofing from runtime authorisation Treat an authenticated or verified identity as an input, not an endpoint, and require behavioural evidence before high-risk actions are allowed to complete.
- Review controls that assume fixed scripts Map where your fraud programme still assumes a bot will repeat the same path, then identify checkpoints that can respond to adaptation inside a live session.
Bottom line: Agentic AI fraud is not just faster bot activity. It combines synthetic identities, adaptive sessions, and legitimate-looking access paths to defeat controls that focus only on who the actor claims to be.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI fraud is an identity governance problem, not just a fraud problem. Once an actor can adapt, retry, and coordinate across sessions, classic bot detection stops being the primary control boundary. The field has to treat fraud as a delegated identity behaviour problem across human, NHI, and autonomous actors. Practitioners should align fraud telemetry, access governance, and session controls around behaviour, not only account proofing.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- 52% of companies can track and audit the data their AI agents access, leaving 48% without full visibility into agent behaviour.
A question worth separating out:
Q: Who should own response when an AI-driven fraud campaign uses compromised credentials?
A: Ownership should sit across fraud operations, IAM, and NHI governance, because the campaign is using both identity abuse and behavioural manipulation. The right response model assigns responsibility for credential containment, session analysis, and account outcome review rather than treating the event as a single-team issue.
👉 Read our full editorial: Agentic AI fraud breaks identity-first defenses at the interaction layer
Identity-first fraud defense collapses when the actor is allowed to adapt after the authentication event. The article shows that the core control assumption is no longer stable identity, but stable behaviour. When the session itself can change tactics, the governance boundary shifts from who the actor is to what the actor does inside the interaction layer. Practitioners should treat behavioural evidence as the primary trust signal, not a secondary one.
A few things that frame the scale:
- A May 2025 Gartner poll of 147 CIOs and IT leaders found that 24% had already deployed AI agents, 50% were experimenting and 17% planned to deploy by the end of 2026.
A question worth separating out:
Q: What is the difference between agent identity and agent behaviour in fraud defence?
A: Agent identity describes who or what the system claims to be. Agent behaviour describes what it does over time, including retries, workflow choices, and escalation paths. In agentic fraud, identity can be legitimate while behaviour is abusive, so governance must evaluate both layers separately.
👉 Read our full editorial: Agentic AI fraud breaks identity-first defenses at the interaction layer